Business email compromise explained
Business email compromise (BEC) is a sophisticated type of cyber fraud targeting organizations through deceptive practices involving email communications. This threat exploits the reliance of businesses on email for corporate correspondence, manipulating trust and authority to execute some sort of unauthorized fund transfers, obtain sensitive information, or move laterally into the IT network.
BEC attack phases
The phases that attackers utilize to conduct BEC attacks are demonstrated in Figure 12.1:
Figure 12.1 – BEC attack phases
Having observed the stages outlined in the figure, let’s dive into each phase with a detailed breakdown:
- Reconnaissance: In this phase, attackers meticulously study the victim organization’s hierarchy, communication patterns, and specific jargon used. If an attacker has access to an account already, they simply run searches within the email system to understand...